CompTIA Cloud+ (CV0-004)SecurityHard

A cloud security architect is tasked with ensuring that all sensitive data stored in a multi-region object storage solution remains accessible only from specific IP ranges belonging to the company's corporate network, regardless of the region. This must be enforced at the network perimeter before data access attempts reach the storage service itself. Which security control is most effective for this requirement?

  1. AImplementing bucket policies with IP condition blocks.
  2. BUtilizing Network Access Control Lists (NACLs) associated with subnets.
  3. CConfiguring Virtual Private Cloud (VPC) endpoints for the storage service.
  4. DDeploying a Cloud Access Security Broker (CASB) to filter storage traffic.
Show answer & explanation

Correct answer: B. Utilizing Network Access Control Lists (NACLs) associated with subnets.

NACLs operate at the subnet level and are stateless, meaning they process inbound and outbound rules independently. They are effective for filtering traffic based on IP addresses at the network perimeter, before it reaches resources within the subnet, making them suitable for blocking access to services from unauthorized IP ranges across regions if applied consistently to relevant subnets.

Why the other options are wrong

  • A. Bucket policies are resource-based and enforce access at the object storage service level, after network traffic has already reached the service. The requirement is to enforce *before* access attempts reach the storage service.
  • C. VPC endpoints provide private connectivity to cloud services from within a VPC, but they don't inherently restrict access based on *external* corporate IP ranges unless combined with other controls like NACLs or firewalls between the on-premises network and the VPC.
  • D. A CASB primarily focuses on securing SaaS application access and data, and while it can provide some network controls, it's not the most direct or efficient tool for blocking traffic at the network perimeter based on IP ranges for multi-region object storage.

NACLs (Network Access Control Lists)

Stateless, subnet-level firewalls that control inbound and outbound traffic to and from subnets in a VPC.

  • Operate at the network perimeter (subnet level).
  • Stateless - separate rules for inbound/outbound.
  • Effective for coarse-grained IP-based filtering.

Memory trick: NACLs guard the subnet's network gates.

More Security questions